SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found.
EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation.
“Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Cohen said. “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.”
Cohen and EFF Senior Staff Technologist Bill Budington reviewed the public developer documentation of dozens of widely used advertising SDKs to identify how they handle and communicate with developers about location data.
In their analysis, they highlighted four advertising SDKs that collect and share a user's location by default for ad targeting whenever the user has given the app location permissions: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. But EFF’s focus on these four does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. In fact, advertising SDKs not discussed in this investigation have been criticized and sued for collecting location data without valid user consent.
“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads,” Budington said. “Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Developers have a responsibility to protect their users’ from these harms, regardless of advertising SDKs’ default settings.”
For the EFF report: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
For more on location data brokers: https://www.eff.org/issues/location-data-brokers
For more on SDKs: https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data
Facts Only
* Advertising SDKs automatically feed users’ location data into systems used by location data brokers.
* The Electronic Frontier Foundation (EFF) investigated the location-sharing practices of various advertising SDKs.
* The investigation examined the pipeline from mobile apps to location data brokers.
* Certain defaults, financial incentives, and unclear documentation facilitate location data sharing without user knowledge or meaningful consent.
* Four advertising SDKs identified by default collection/sharing are InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads.
* Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, tracking union organizers, and tracking US military personnel.
* The EFF noted that developers have a responsibility to protect users from harms caused by location data leakage.
Executive Summary
Advertising software development kits (SDKs) provided by advertising companies automatically feed users’ location data into systems used by location data brokers, according to an Electronic Frontier Foundation report. The investigation examined the location-sharing practices of various advertising SDKs to understand the flow of location data from mobile apps to brokers. The probe revealed that certain defaults, financial incentives, and unclear documentation facilitate location data sharing without meaningful user consent.
The EFF specifically highlighted four advertising SDKs—InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads—that collect and share a user's location by default for ad targeting when location permissions are granted. While the investigation focused on these four, other SDKs have also been criticized and sued for collecting location data without valid consent. The analysis suggests that developers, regulators, and legislators must intervene to prevent apps from leaking location data to advertisers and brokers.
Full Take
The pattern observed is one where proprietary development tools, introduced under the guise of monetization, create systemic vulnerabilities by embedding non-consensual data practices into default settings, effectively externalizing user privacy costs onto the end-user. The distinction between what a developer *chooses* to do and what an SDK *defaults* to represents a failure in establishing protective boundaries around sensitive personal information. The implication is that commercial incentives systematically erode the principle of informed consent by creating defaults that maximize data extraction, regardless of explicit user settings.
This mechanism echoes historical patterns where ostensibly neutral technologies are leveraged for surveillance or control. The focus on location data from advertising platforms being repurposed for state and intelligence tracking suggests a systemic risk where the infrastructure built for commerce becomes an unwitting conduit for broader societal harms. The core conflict lies between the economic imperative driving SDK design and the fundamental requirement for individual autonomy over one's physical presence.
What shifts in perspective must occur to hold developers accountable when their tools are demonstrably implicated in activities ranging from targeted advertising to government surveillance? What frameworks are necessary to re-establish meaningful consent when default settings prioritize corporate data flow? Does focusing on specific SDKs sufficiently address the broader systemic responsibility of the entire digital ecosystem?
Sentinel — Human
The text appears to be a factual summary of an investigation by the EFF, structured around expert testimony and specific findings, suggesting a journalistic foundation.
